css-scroll-anchor-polyfill@1.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17485
Ecosystem
npm
Summary
Package is published as css-scroll-anchor-polyfill but its index.js is empty and its contents impersonate internal Wix thunderbolt registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) with a shipped registry-manifest.min.json mapping them to parastorage.com URLs. The declared purpose (a CSS scroll-anchor polyfill) is unrelated to the shipped code. thunderboltRegistry.js contains a top-level IIFE that executes on require: it runs local reconnaissance via child_process.execSync (cat /etc/hosts, whoami, id, pwd, ifconfig/ip addr, hostname, uname -a) and transmits the collected output together with a beacon (node version, process.platform, pid) via fetch to a hardcoded HTTP endpoint at http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. Any internal build that resolves one of the impersonated thunderbolt names to this public package and requires the corresponding submodule triggers the reconnaissance and exfiltration path.
Source: amazon-inspector (36596ba9b9d8c0f994abe3cd87783f4f0dc880e63d55374d3555347ce349fab2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.